PKI - Certification Authority (CA): IssuingCA, certificate with "unknown error"

49885604 145 Reputation points
2024-04-28T13:56:17.1266667+00:00

Hi everyone,
I have a couple of CAs that I manage, they are Enterprice CA with Root Server in workgroup (not in domain). I have an error in the IssuingCA regarding the certificate and I think it happens when the Root CRL expires, if I copy the Root CRL into the SubCA and into the CertData folder the error disappears. But this renewal should be automatic. Is there some configuration error in your opinion?
See the image error.

Kind regards,

Alessio

IssuingCA_certificateError_2.png

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,481 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,209 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,936 questions
Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,390 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Daisy Zhou 18,721 Reputation points Microsoft Vendor
    2024-04-29T12:24:13.6033333+00:00

    Hello 49885604,

    Thank you for posting in Q&A forum.

    If the CRL on root CA expired, you should update and publish it to domain manually.

    Here is a similar thread for your reference.

    https://learn.microsoft.com/en-us/answers/questions/750987/generic-unknown-status-in-pkiview-after-migration

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


  2. MukeshAgarwal-MSFTE 0 Reputation points
    2024-05-06T18:47:48.1366667+00:00

    Since the RootCA is non domain join the CRL update needs to be done manually.

    0 comments No comments